Data protection information
Table of Contents
1. Name and Address of the Data Controller
2. Data Protection Officer
3. Provision of the Website and Creation of Log Files
4. Email, Phone, and Contact Form
5. Online Reception (321 MED)
6. Application Process
7. Social Media
8. Links to Third-Party Websites
9. Rights of the Data Subject
1. Name and address of the data controller
MVZ am InnKlinikum Mühldorf am Inn gGmbH, as the data controller within the meaning of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications and Digital Services Data Protection Act (TDDDG), and other data protection regulations.
Comprehensive information about our hospital can be found in the legal notice.
2. Data Protection Officer
We have appointed an external data protection officer.
You can contact the Data Protection Officer at MVZ am InnKlinikum Mühldorf am Inn gGmbH at any time at:
Benno Wrobel
e:los GmbH
Heideweg 25
92318 Neumarkt
Phone +49 9181 522 94 0
Email: datenschutzbeauftragter@innklinikum.de
datenschutz@elos-net.de
3. Hosting of the website and creation of log files
3.1 Description and Scope of Data Processing
Each time the website is accessed, the system—that is, the web server—automatically collects information from the user’s computer or device.
The following data is collected in this process:
- Information about the browser type and version being used
- The operating system of the user’s device
- The user’s Internet service provider
- The user’s IP address
- Date and time of access
- The previous website from which the user arrived at my website
3.2 Legal Basis for Data Processing
The legal basis for the temporary storage of this data and the log files is Article 6(1)(f) of the GDPR (our legitimate interest as the website operator).
3.3 Purpose of Data Processing
The system must temporarily store the user’s IP address in order to deliver the website to the user’s computer. To do so, the user’s IP address must necessarily be stored for the duration of the session.
The data listed above is stored in log files to ensure the proper functioning of the website. In addition, this data is used to optimize the website and to ensure the security of the information technology systems (e.g., for attack detection).
In this context, the data is not analyzed for marketing purposes.
3.4 Duration of Storage
The data listed above will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of data collected for the purpose of providing the website, this occurs when the respective session ends.
If the data is stored in log files, this occurs no later than 14 days.
4. Email, Phone, and Contact Form
4.1 Description and Scope of Data Processing
You can contact us using the email addresses provided, our phone numbers, or the contact form (“Feedback”). We will store the personal data you provide when contacting us.
4.2 Legal Basis for Data Processing
The legal basis for processing the data you provide to us when sending an email or contacting us by phone is Article 6(1)(f) of the GDPR (our legitimate interest in responding to your inquiry).
The legal basis for processing the data you provide to us when submitting an inquiry via the contact form is Article 6(1)(a) of the GDPR (consent).
If the request is aimed at entering into a contract, the additional legal basis for the processing is Article 6(1)(b) of the GDPR (performance of a contract/precontractual measures, e.g., scheduling an appointment).
4.3 Purpose of Data Processing
We process this personal data to handle your contact request and respond to your inquiry.
4.4 Duration of Storage
The data listed above will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. For personal data transmitted via email, contact form, or telephone, this is the case once the respective conversation with you has ended and there are no statutory retention periods that prevent deletion.
4.5 Right to Object
You have the right to object to the processing of your data at any time.
The appeal must be sent to the following email address:
datenschutzbeauftragter@innklinikum.de.
In this case, all personal data stored in the course of establishing contact will be deleted, provided that no statutory retention periods prevent such deletion.
5. Online Reception (321 MED)
5.1 Description and Scope of Data Processing
We have integrated the 321 MED online reception service into our website. This service allows you to easily communicate digitally with our locations and medical specialties (e.g., schedule appointments, reschedule appointments, cancel appointments, request prescriptions, request or send test results, request referrals).
When you use the online reception desk and enter information there, the data you provide (e.g., name, date of birth, contact information, health insurance status, and medical concerns) is transmitted directly to the provider’s servers in encrypted form.
To enable the online reception service and prevent misuse, we also collect your IP address and device-related technical data (e.g., browser type, operating system).
The recipient of the data is the technical service provider:
321 MED GmbH, Am
heimlichen Grund 5, 92421 Schwandorf.
We have entered into a data processing agreement (DPA) with 321 MED GmbH in accordance with Article 28 of the GDPR. This agreement ensures that the service provider processes the data exclusively in accordance with our instructions and in compliance with the strictest security standards. Data is not transferred to third countries outside the EU; all data is stored exclusively on servers in an ISO 27001-certified data center in Germany.
For more information on data protection for the Online Reception service, please visit:
5.2 Legal Basis for Data Processing
The processing of your data in connection with the online reception service is based on your explicit consent pursuant to Article 6(1)(a) of the GDPR, as well as – insofar as health data is concerned – in accordance with Article 9(2)(a) of the GDPR, which you provide when using the online reception service. To the extent that the use of the service serves to initiate or fulfill a treatment contract, the additional legal basis is Article 6(1)(b) of the GDPR (performance of a contract/precontractual measures).
5.3 Purpose of Data Processing
The integration of the online reception desk on our website is intended to streamline our organizational processes, reduce the load on our telephone network, and provide a secure, modern communication channel for our patients.
5.4 Duration of Storage
Your data will be stored for as long as necessary to process your request or as required by statutory retention periods.
5.5 Right to Object
You have the right to object to the processing of your data at any time.
Your objection should be sent to the following
email address:
datenschutzbeauftragter@innklinikum.de.
In this case, all personal data stored in connection with your use of the online reception will be deleted, provided that no statutory retention periods prevent such deletion.
6. Application Process
6.1 Description and Scope of Data Processing
We offer you the opportunity to apply for current job openings or apprenticeship positions through our application form (under “Careers” → “OUR JOB OPENINGS” → “View Job Posting” → “APPLY NOW” → “Application Form”).
When you click “APPLY NOW,” you will be redirected to our career portal or to the application form provided by the vendor of our applicant tracking system.
The provider of our applicant tracking system is:
SD Worx GmbH, Kurfürstendamm 11,
DE-10719 Berlin
SDWorx GmbH Data Center: Fujitsu Services GmbH, Mies van-der-Rohe-Straße 8, DE-80807 Munich.
You can find the privacy policy for SD Worx GmbH’s services at:
https://www.sdworx.de/de-de/datenschutzerklaerung
When you apply for a position, we electronically collect and process your applicant and application data in order to manage the application process.
6.2 Legal Basis for Data Processing
The legal basis for the processing of your data as part of a job application process is Section 26(1) of the Federal Data Protection Act (BDSG) in conjunction with Article 88(1) of the General Data Protection Regulation (GDPR).
If you expressly consent to the longer-term storage of your data—for example, for inclusion in a database of applicants or prospective clients—the data will be further processed based on your consent. The legal basis in this case is Article 6(1)(a) of the GDPR.
You may revoke your consent at any time in accordance with Article 7(3) of the GDPR by notifying us, effective for the future.
6.3 Purpose of Data Processing
Your data will be processed for the purpose of conducting the application process.
6.4 Duration of Storage
If an application is rejected, we will delete the data submitted to us six months after notification of the rejection.
Once the application process is complete, we will retain your personal data for as long as we are required to do so by law or as long as you have given us your consent to do so.
However, the data will not be deleted if legal provisions—such as the burden of proof under the AGG—require it to be retained for a longer period, or until the conclusion of legal proceedings.
The legal basis in this case is Section 24(1)(2) of the Federal Data Protection Act (BDSG).
6.5 Right to Object
You have the right to object to the processing of your data at any time.
The appeal must be sent to the following email address:
datenschutzbeauftragter@innklinikum.de.
In this case, all personal data collected during the application process will be deleted, provided that no statutory retention periods prevent such deletion.
7. Social Media
Description of Data Processing
To support our public relations efforts, we are currently using the following social media platforms:
When you visit our website, no personal data is initially shared with any social media provider.
Personal data will only be transmitted if you click on one of the buttons or logos.
We have no control over the data collected or the data processing procedures, nor are we aware of the full scope of the data collection, the purposes, or the retention periods. Since providers collect data primarily through cookies, we recommend that you delete all cookies via your browser’s security settings before clicking the relevant button.
7.1 Description and Scope of Data Processing
We have included a button (logo) on this website that links to the social network Instagram. Instagram allows users to share photos and videos and also to repost such content on other social networks.
The company that operates Instagram’s services in Europe is Meta Platforms Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Instagram may receive information indicating that you have visited our website if you are logged into Instagram at the same time you access our website. This occurs when you click on the Instagram logo. If you do not want this information to be transmitted to Instagram from
, you can prevent this by logging out of your Instagram account before clicking on the logo on our website.
We have no control over the data collected by Instagram or its data processing procedures, nor are we aware of the full scope of data collection, the purposes of processing, or the retention periods. We also have no information regarding the deletion of collected data by Instagram. The social media provider’s Terms of Use and Privacy Policy apply.
For more information and Instagram’s current privacy policy, visit https://help.instagram.com/155833707900388 and https://privacycenter.instagram.com/policy .
7.2 Legal Basis and Purpose of Data Processing
You will be redirected to the linked platform based on your voluntary click on the button (logo) (Art. 6(1)(a) of the GDPR).
7.3 Right to Object and Remedies
You have the right to object to the creation of user profiles; to exercise this right, you must contact the social media provider. It is also possible to block social media providers using browser add-ons. Please note that you can prevent the association described above by logging out of your Instagram account before visiting the website and deleting the cookies used by Instagram.
By changing the settings in your web browser, you can disable or restrict the use of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically.
8. Links to Third-Party Websites
8.1 Description and Scope of Data Processing
This website contains links to third-party websites.
The links are clearly marked in each case.
In addition to the link to the social network Instagram (see 7. Social Media), this also applies to a link to our career portal or the application form provided by the vendor of our applicant tracking system (see 6. Application Process).
If you click on any of the links (or buttons, logos, or text), you will be redirected to the corresponding website.
If you like our website, click on the “Shytsee” logo, and you’ll be redirected to the website of the advertising agency that designed our site.
With regard to websites that have been and continue to be designed and provided by third parties, we have no control over the design, content, or functionality of these third-party services.
Please note that third-party services linked from our website may install their own cookies on your device or collect personal data.
Please check directly with the providers of these linked third-party services as needed (e.g., by reviewing their privacy policies).
8.2 Legal Basis for Data Processing
The legal basis for redirecting you to the linked website is Article 6(1)(a) of the GDPR (your consent, given by voluntarily clicking on the link in question).
8.3 Purpose of Data Processing
Links to third-party websites are provided to give you easy access to the relevant information.
9. Rights of the Data Subject
If a user’s personal data is processed, that user is a “data subject” as defined by the GDPR. As the data controller, we are required to grant the user the following rights:
- Right to Information
- Right to Correction
- Right to Restriction of Processing
- Right to Erasure
- Right to Information
- Right to Data Portability
- Right to Object
- Right to Withdraw Consent Under Data Protection Law
- Right to file a complaint with a data protection supervisory authority
Note on Withdrawing Consent:
Although a data subject has the right to revoke his or her declaration of consent under data protection law at any time, this does not affect the lawfulness of the processing carried out on the basis of that consent up until the time of revocation.
Information on Filing a Complaint with a Regulatory Authority:
Without prejudice to any other administrative or judicial remedy, a data subject has the right to lodge a complaint with a supervisory authority—in particular in the Member State where the user resides, where the user works, or where the alleged infringement occurred — if the user believes that our processing of their personal data violates the GDPR.
Notice Regarding the Transfer of Data to Third Countries
The GDPR requires that, when personal data is transferred to third countries (outside the European Economic Area), there be safeguards ensuring an adequate level of data protection in those countries.
For data transfers to the United States, this is the EU-U.S. Data Privacy Framework.
This is contingent on the organizations in question being certified under the EU-U.S. Data Privacy Framework (such as Meta Platforms—Instagram).